Skip to content

Security: gemmology-dev/crystal-api

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Do not open a public issue
  2. Email the maintainers directly (see repository for contact)
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix timeline: Depends on severity

Security Best Practices

When using Gemmology packages:

  • Keep packages updated to the latest versions
  • Review CDL input from untrusted sources
  • Be cautious with file paths in CLI tools
  • Use virtual environments for isolation

There aren’t any published security advisories